Get Demo
↑

ISO 27001 Risk Assessment: Methodology, Template and Examples

Practical ISO 27001:2022 risk assessment methods, a sample risk register template, and examples teams can adapt under Clause 6.1.2.

Published: September 2026 Compliance · ISO 27001 8–12 min read

ISO/IEC 27001:2022 requires an information security risk assessment process (6.1.2) and risk treatment that produces a Statement of Applicability (6.1.3). This page gives a practical methodology outline and an example register — not a substitute for reading the standard.

Related: SoA template guide · ISMS scope · Gap analysis.

Method freedom, process discipline: Auditors care that criteria, owners, results, and treatment decisions are consistent and retained as documented information — not that you copied a vendor matrix.

Common Method Choices

Sample Risk Register Columns

Field
Purpose
Risk ID
Stable identifier for treatment tracking
Asset / process
What is at stake inside the ISMS scope
Threat / scenario
What could go wrong
Likelihood / impact
Per your 6.1.2 criteria
Risk level
Before and after treatment
Treatment option
Mitigate, avoid, share, accept
Controls (SoA link)
Annex A and/or designed controls
Owner / due date
Accountability

Example Rows (Illustrative)

Build Your ISO 27001 Programme with Continuous Evidence

CyberSilo CSA maps ISMS artefacts and Annex A control evidence; ThreatHawk supports logging and monitoring proof for technological controls.

Frequently Asked Questions

Does ISO 27001 prescribe one risk method?

No. Clause 6.1.2 requires a defined process with criteria for accepting risks and identifying acceptable risk levels. Asset-based, scenario-based, or hybrid methods are all used in practice.

How often must risk assessment run?

At planned intervals and when significant changes are proposed or occur (Clause 8.2), using the criteria established in 6.1.2.

Is the Statement of Applicability part of risk treatment?

Yes. Producing the SoA is part of Clause 6.1.3 risk treatment.

SoA guide · Gap analysis · Mandatory documents · ISO 27001 hub

📰 More from CyberSilo

Latest Articles

Stay ahead of evolving cyber threats with our expert insights

✅ Link copied!